Privacy notice at a glance
Sarth AI Tech LLP, operating the SarthiAI service (collectively, “SarthiAI”, “we”, “us” or “our”), provides AI‑enabled educational and learning‑support services through its applications, websites and institution‑facing interfaces. SarthiAI is operated from India, with its primary application database and core profile storage hosted in Mumbai, India.
We collect only the information reasonably required to create and secure accounts, provide learning features, generate AI responses, personalise the learning experience, process subscriptions, support users, meet legal obligations and improve the safety and reliability of the service. Depending on how you use SarthiAI, this may include account details, age and guardian details, education and learning‑profile data, prompts, chat transcripts, voice transcripts, uploaded files, AI outputs, progress information, transaction records and limited technical or security logs.
SarthiAI uses artificial intelligence. AI responses can be inaccurate, incomplete or unsuitable and should be verified, particularly before they are used for examinations, assignments, health, safety or other important decisions. AI outputs are educational aids and should not be treated as professional advice (including legal, medical, financial or other regulated advice).
Children may use SarthiAI only through an approved parent/guardian‑managed or institution‑managed flow. Where law requires verifiable parental or guardian consent, the child account will not be activated until such consent has been obtained through the approved process, with a mandatory parental checkbox built into the child‑account registration flow.
We do not sell personal data, and we do not use children’s personal data for targeted advertising, behavioural advertising or profiling that is detrimental to their well‑being. SarthiAI does not use automated network telemetry, cookies, device identifiers or IP addresses to build behavioural profiles or targeted advertising segments for any user.
You may exercise applicable rights, withdraw consent, change communication preferences or request account deletion through the in‑app settings hub, via our dedicated deletion portal at sarthiai.co.in, or by contacting our published privacy email address.
1About this Policy
This Privacy Policy explains how SarthiAI collects, receives, uses, discloses, stores, protects and deletes personal data when a person:
- visits a SarthiAI website or landing page;
- creates or uses an individual, parent‑managed or institution‑linked account;
- uses text, voice, upload, quiz, flashcard, summary, lesson‑path, progress or other learning features;
- purchases or manages a subscription;
- communicates with SarthiAI for support, feedback, grievances, security or other purposes; or
- interacts with SarthiAI through a school, college, coaching centre, employer, teacher or other educational institution.
This Policy should be read together with the SarthiAI Terms of Service, Cookie and Tracking Technologies Policy, applicable in‑product notices and, for institution‑managed use, the agreement between SarthiAI and the relevant institution.
This Policy is designed with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules made under it, to the extent brought into force and applicable, together with other applicable Indian privacy, information‑technology, cybersecurity, consumer and platform requirements including the Information Technology Act, 2000, CERT‑In directions, and relevant Google Play and Apple App Store rules. Where a legal requirement is introduced or brought into force in phases, SarthiAI will apply it from the date and to the extent it becomes applicable.
2Who is responsible for personal data
For direct‑to‑consumer accounts, Sarth AI Tech LLP ordinarily determines why and how personal data is processed and acts as the Data Fiduciary for that processing under the DPDP Act.
For institution‑linked accounts, responsibility depends on the actual arrangement and the purpose of processing. The institution and SarthiAI may each act as an independent Data Fiduciary for specified activities, or SarthiAI may process certain data as a Data Processor on the institution’s documented instructions. The applicable institution agreement and data‑processing terms will identify the parties’ respective responsibilities, and nothing in this Policy transfers a statutory obligation merely because an institution creates or manages an account.
The institution’s own privacy notice may also apply to information it collects or controls. Questions concerning an institution’s independent use of learner data should be directed to that institution.
3Children and age‑appropriate use
For this Policy, a “Child” means a person below 18 years of age or such other threshold as may be prescribed by applicable law.
3.1 Age screening
SarthiAI may ask for date of birth, age range, class or another age indicator to determine the appropriate account route and safeguards. Users must not misstate age to bypass child protections or to gain access to adult‑only features.
3.2 Parent or guardian‑managed accounts
Where a Child uses SarthiAI outside an institution‑managed arrangement, the account must be created or approved by the Child’s parent or lawful guardian. Before processing that Child’s personal data where verifiable consent is legally required, SarthiAI will take reasonable technical and organisational measures to verify that the person providing consent is an identifiable adult and represents that they are the parent or lawful guardian.
The child‑account signup flow includes a mandatory parent/guardian checkbox with clear wording, such as “I am a parent or lawful guardian creating this account for my child”, which must be selected by the adult and is recorded as part of the consent log to comply with Section 9 of the DPDP Act. Verification methods may use reliable details already held by SarthiAI, device‑level assurances or a legally recognised identity, age or token‑based service, as these become available in the Indian ecosystem.
Parents and guardians represent and warrant that the information they provide during registration is true, accurate and complete, and that they have lawful authority to create and manage the child’s account. Parents and guardians are responsible for maintaining the confidentiality of child‑account credentials, supervising use and immediately informing SarthiAI if they suspect unauthorised access or misuse, and they agree that inaccurate declarations or misuse may give rise to responsibility under applicable law, without limiting SarthiAI’s duties as a Data Fiduciary.
3.3 Institution‑managed accounts
An institution may facilitate registration, provide account details or manage learner access under a written agreement. The institution must have lawful authority to provide the information and must deliver all required notices and obtain all required permissions or consents, including any parental or guardian consents required under applicable law.
For organizational and institutional enrollments, student age, identity, and baseline enrollment status verification are managed contractually by partner institutions utilizing verified institutional records. In such school-managed paths, SarthiAI processes student registration parameters strictly on the basis of the institution's administrative mandate and representations of lawful authority to deploy educational services. Where direct, verifiable parental or guardian consent is independently required under applicable rules, SarthiAI does not treat institutional enrollment as a unilateral waiver of data principal rights. In such instances, or where a minor registers outside an institutional gate, account activation remains conditionally gated until verifiable parental consent is explicitly captured via a linked parent/guardian credential dashboard or a designated mobile/email verification flow.
3.4 Child protections
Unless a lawful exemption applies and is documented, SarthiAI will not:
- process a Child’s personal data without the required verifiable parental or guardian consent;
- undertake tracking or behavioural monitoring of Children for advertising;
- serve targeted or personalised advertising to Children;
- profile a Child in a manner likely to cause a detrimental effect on the Child’s well‑being;
- knowingly permit a Child to disclose unnecessary identification, contact, financial or sensitive information through open‑text prompts or uploads; or
- enable a Child to communicate with unknown persons through the service without age‑appropriate safeguards and required adult controls.
Parents and guardians should supervise use, teach Children not to place unnecessary personal information in prompts or uploads, and review important AI outputs, particularly for examinations, assignments and high‑stakes decisions. To report a child‑safety concern, users or institutions may use the in‑app reporting paths described in Section 7.3 or contact the child‑safety contact published on SarthiAI’s website.
4Personal data we may collect
The categories below apply only where the relevant feature is enabled and used.
4.1 Account and identity information
SarthiAI may collect and process the following information when you create and use an account:
- name, display name and username;
- email address and, where enabled, mobile number;
- password hash and authentication or session information;
- date of birth, age range and age‑screening result;
- Google, Apple or other single‑sign‑on identifier and profile fields authorised by the user; and
- account status, subscription tier, language, region and preferences.
4.2 Parent, guardian and institution information
Where applicable, SarthiAI may collect:
- parent or guardian name, contact details, relationship confirmation, consent record and verification result;
- school, college, coaching centre, employer or institution name;
- learner identifiers, enrolment details, class, cohort, teacher and administrator associations; and
- records of permissions, administrator actions and institution support requests.
4.3 Education and learning‑profile information
Depending on your learner persona, SarthiAI may collect:
- board, curriculum, class or grade, academic stream, subjects, degree, discipline, academic year and language medium;
- declared region or country and, where relevant, institution context;
- selected interests, preferred difficulty level, study plan and accessibility or interface preferences;
- quizzes attempted, responses, scores, flashcards, topics covered, time and frequency of use, progress indicators and other learning interactions; and
- feedback, ratings and corrections supplied by a user, parent, educator or institution.
SarthiAI designs learning‑profile attributes to support fair and transparent educational purposes, and such attributes are not used for unrelated consequential decisions such as admission or employment unless an institution has expressly authorised a lawful process.
4.4 Prompts, conversations and AI content
To provide conversational and AI‑enabled features, SarthiAI may process:
- text prompts, questions, instructions and conversation history;
- text transcripts derived from voice commands, where voice features are used;
- AI‑generated answers, summaries, quizzes, flashcards, explanations and lesson paths;
- content‑safety flags, user reports and moderation outcomes; and
- contextual information supplied to an AI system to answer a request.
Users should not include Aadhaar numbers, government identifiers, financial credentials, medical records, private contact details, examination credentials or another person’s confidential information in prompts or uploads unless a feature expressly requires it and provides a specific notice.
4.5 Voice and audio information
Where voice features are used, SarthiAI may receive microphone input and convert it into a text transcript to support conversational learning. Raw audio is processed only as necessary to generate the transcript and is not retained beyond the technical window required for conversion, while the resulting text transcripts may be stored as part of your conversation history.
4.6 Uploaded content
Users may upload documents, text, images, spreadsheets or supported audio files for educational processing. Uploaded content may contain personal data about the user or others, and SarthiAI will process it only to generate summaries, flashcards, quizzes, automated lesson paths and related educational outputs, and for safety, security and legally permitted purposes. Users and institutions are responsible for having the right and lawful authority to upload such content.
4.7 Device, app, website and security information
SarthiAI and its service providers may automatically receive limited technical and security information reasonably required to operate and secure the service, such as crash, diagnostic, performance, request, timestamp and authentication logs.
SarthiAI practices strict data minimisation and does not track, store or log automated network telemetry, tracking cookies, unique device identifiers or user IP addresses for cross‑service tracking, user profiling or targeted advertising, including in child‑directed experiences. However, in line with CERT‑In cybersecurity directions and to protect the integrity of the service, SarthiAI maintains standard system‑access, authentication and security‑event trails for a mandatory rolling baseline period of one year from the date of log creation, and longer only where justified for security or legal purposes. These logs are used solely for security, reliability, abuse detection and compliance, and are not used to build behavioural advertising profiles.
4.8 Payments, subscriptions and transactions
Payment processors and app stores process payment credentials under their own terms. SarthiAI may receive transaction identifiers, plan details, amount, currency, tax, payment status, renewal status, refund status and limited billing information necessary for accounting and support. SarthiAI does not receive complete card or banking credentials unless expressly stated at checkout in a dedicated payment interface.
4.9 Communications and support
We may collect messages, support tickets, grievance details, call or meeting notes, survey responses, marketing preferences and records required to investigate a request or dispute. These records are used to respond to queries, resolve issues, improve service quality and comply with legal obligations.
5How we collect personal data
We collect personal data:
- directly from users, parents, guardians, educators and administrators;
- from an institution that lawfully onboards or manages an account;
- automatically from the app, website, device, browser and integrated SDKs, limited to what is necessary for core operation and security, without telemetry‑based behavioural tracking;
- from authentication, payment, hosting, AI, speech, analytics, communications and support providers engaged as processors; and
- from public or lawful sources where necessary to investigate fraud, abuse, intellectual‑property complaints or security incidents.
Where third‑party SDKs or permissions are used, their purposes and controls will be disclosed in the Cookie and Tracking Technologies Policy and in‑product notices.
6Why we process personal data
Depending on the relationship and feature, SarthiAI may process personal data to:
- create, authenticate, administer and secure accounts;
- determine the appropriate age route and apply child protections;
- obtain, record and manage consent or parental/guardian authorisation;
- provide AI chat, explanations, summaries, flashcards, quizzes, study plans, voice transcription and upload‑based tools;
- personalise content to the user’s declared curriculum, level, language, interests and learning goals;
- remember context and allow users to revisit permitted conversation and learning history;
- provide progress information to the user and, where lawfully authorised, a parent, guardian, educator or institution;
- process subscriptions, renewals, cancellations, refunds, invoices and taxes;
- provide support, respond to grievances and communicate service or policy changes;
- detect abuse, academic‑integrity misuse, harmful content, security threats, fraud and violations of the Terms;
- test, debug, maintain and improve service quality, reliability, safety and accessibility using data that is aggregated, de‑identified or otherwise minimised where reasonably possible;
- establish, exercise or defend legal claims and comply with valid legal demands; and
- meet obligations under applicable privacy, consumer, cybersecurity, tax, accounting, child‑safety and app‑platform requirements.
SarthiAI relies on consent where consent is the appropriate legal basis under the DPDP Act. It may also process personal data for uses recognised as legitimate uses under applicable Indian law, or where processing is necessary to comply with law, respond to a medical emergency, protect against a threat to life or for another legally permitted ground. Consent requests will be specific, clear and capable of being withdrawn with comparable ease, although access to optional features may be unavailable where the data is necessary to provide that feature and consent is withdrawn.
7AI and large‑language‑model processing
SarthiAI may combine retrieval systems, curated educational material and one or more third‑party or proprietary AI models to generate responses. For a request to be processed, relevant prompts, conversation context and portions of uploaded material may be transmitted to AI providers engaged as processors under written contracts.
A current list of key AI and infrastructure processors is maintained on SarthiAI’s website and may be updated from time to time, with appropriate notice where required by law.
7.1 Model training and improvement
Operational processing needed to answer a request is different from training a general model. Unless the account owner has separately opted in after receiving a clear notice, SarthiAI will not use identifiable prompts, transcripts, uploaded content or a Child’s personal data to train or fine‑tune a general‑purpose AI model.
SarthiAI may use de‑identified, aggregated or carefully sampled information to evaluate safety and quality, subject to access controls and the commitments in this Policy. Human review of AI interactions, if used, will be limited, authorised, logged and disclosed, and will focus on safety, abuse detection and quality assurance rather than arbitrary surveillance.
7.2 AI limitations and fairness
AI output may be incorrect, outdated, incomplete, biased, unsafe or unsuitable for a particular syllabus, learner or context. SarthiAI does not use AI output as the sole basis for admission, expulsion, grading, certification, employment or another decision producing a similarly significant effect unless the relevant institution has authorised a lawful process with appropriate human review and notice.
Users, parents and educators should independently review and verify important AI outputs, especially where they are used for examinations, assignments, health‑related decisions or other high‑impact purposes.
7.3 Safety reporting
To satisfy platform AI‑generated content policies and support responsible use, SarthiAI provides an intuitive, visible in‑app reporting tool directly alongside every generative AI output, allowing users to instantly flag inaccurate, offensive, unsafe or inappropriate content for human moderation. Reports may be reviewed and used to improve filters, moderation and safety controls and may contribute to de‑identified safety analytics.
9International processing
SarthiAI’s primary database and core profile storage are securely hosted in Mumbai, India, within controlled infrastructure that ring‑fences account profiles, learning‑persona parameters and institutional records to that environment.
However, to deliver real‑time AI capabilities, live interactive AI chat prompts, conversation strings and relevant snippets of uploaded content are transiently routed via API endpoints to Cloudflare Worker AI globally for inference, because specialised enterprise GPUs execute across distributed cloud networks. This processing is handled strictly in memory, features absolute zero data retention by the processor once an API response is sent, and is contractually prohibited from being used for AI model training, behavioural profiling or cross‑service tracking.
Some providers engaged for support, content delivery, disaster recovery or specialist security services may process or transiently route information outside India. Before enabling such processing, SarthiAI will assess the provider, enter appropriate contractual protections and comply with restrictions or government requirements applicable to transfers or overseas access, including any conditions imposed under the DPDP Act and CERT‑In directions. The Policy will not promise India‑only processing where AI inference, support or vendor personnel operate internationally; instead, cross‑border processing will be disclosed in a manner consistent with this Section.
10Retention and deletion
SarthiAI retains each category of personal data only for the period reasonably required for the disclosed purpose, legal obligations, security, dispute resolution and enforcement.
10.1 Retention schedule and deletion behaviour
The retention and deletion behaviour for key categories is as follows:
- Account and profile data: retained while the account remains active and the educational purpose continues. Upon a user triggering an account closure via either channel, SarthiAI treats the action as a withdrawal of consent and loss of processing purpose. SarthiAI will immediately initiate an automated command script to remove the user’s active profile, educational persona parameters, and conversation transcripts from active application databases as soon as reasonably practicable. Provided, however, that standard system access metadata, transaction identifiers, and network security logs shall be securely archived and retained for the statutory period required under applicable CERT-In cybersecurity directions and financial tracking mandates before permanent erasure.
- Parent/guardian consent and verification records: retained for a period reasonably required to demonstrate compliance with child‑specific obligations under the DPDP Act and to defend related legal claims, and then deleted or irreversibly de‑identified.
- Prompts and chat history: retained while the account remains active to support revisiting permitted sessions, progress tracking and educational continuity; deleted or irreversibly de‑identified from active systems immediately upon user‑triggered account deletion.
- Uploaded content and generated study material: retained while the associated account remains active and the feature remains in use, and deleted or de‑identified from active systems on account deletion or feature‑specific erasure, subject to legal obligations.
- Raw audio, if any: processed only transiently to generate text transcripts and not retained beyond the conversion window; transcripts follow the chat‑history retention described above.
- Learning‑progress and institution reports: retained in line with the applicable institution contract or for a period reasonably required to support pedagogy, audit and regulatory requirements, then deleted or de‑identified.
- Support and grievance records: retained for a period reasonably necessary to investigate, resolve and document grievances and regulatory interactions, and then deleted or appropriately minimised.
- Billing, tax and transaction records: retained for the statutory periods required under tax and accounting law, and longer only where necessary for disputes or enforcement.
- Security and system logs: retained for one year from the date of log creation, in strict compliance with domestic cybersecurity (CERT‑In) directions, and longer only where justified for security or legal purposes.
- Backups: stored in encrypted form and cleared through secure backup‑rotation cycles; data restored from backups is protected from ordinary use and re‑deleted where practicable in accordance with this Policy.
When an account is deleted, SarthiAI deletes or irreversibly de‑identifies associated personal data from active systems, except information that must be retained for legal compliance, fraud and security, unresolved transactions, disputes or enforcement. Deletion from encrypted backups occurs through the regular backup‑expiry cycle.
10.2 Data masking and pseudonymisation
To comply with the DPDP Act’s principles of data minimisation and reasonable security safeguards, SarthiAI applies data‑masking and pseudonymisation protocols strictly to active session parameters, rather than indiscriminately across all data. During live sessions and internal processing, SarthiAI dynamically pseudonymises core User IDs and corresponding conversation transcripts using isolated session tokens, so that identity fields are logically separated from content fields.
These measures ensure that core profile attributes, account identifiers and institutional records remain ring‑fenced within the Mumbai active environment, while session‑level processing uses reduced identifiers consistent with security and fairness requirements. Over time, SarthiAI may further expand anonymisation controls (such as cohort‑level aggregation) without reducing user rights under this Policy.
11Security and personal‑data incidents
SarthiAI uses reasonable and proportionate technical and organisational safeguards appropriate to the nature of the information and foreseeable risks. These may include encryption in transit and at rest where appropriate, password hashing, least‑privilege access, multi‑factor authentication for privileged access, environment segregation, secure development, vulnerability management, monitoring, backup and recovery, incident response, access logging, vendor diligence and staff confidentiality and training.
No system is completely secure. Users must protect credentials and promptly report suspected compromise using the support channels described in Section 17. Where a personal‑data breach or reportable cybersecurity incident occurs, SarthiAI will investigate, mitigate, preserve necessary evidence and notify affected persons, the Data Protection Board of India, CERT‑In, app platforms or other authorities within the form and timeline required by the law then in force.
This Policy does not condition notification only on a subjective assessment that harm is “likely” where the applicable law requires notification more broadly; SarthiAI will follow the thresholds imposed by DPDP, IT Act rules and CERT‑In directions.
12User choices and rights
Subject to applicable law, identity verification and lawful exceptions, a person may:
- obtain information about personal data being processed and the processing activities;
- request correction, completion or updating of inaccurate or incomplete personal data;
- request erasure of personal data that is no longer required for the stated purpose;
- withdraw consent with comparable ease;
- manage communications and cookie or SDK preferences;
- request account deletion and, where offered, export of learning material;
- nominate another individual to exercise applicable rights in the event of death or incapacity;
- raise a grievance and, after exhausting SarthiAI’s grievance process where required, approach the competent authority; and
- exercise any additional right available under applicable law.
Requests may be submitted through in‑app controls, via rights‑request interfaces published on SarthiAI’s website, or by contacting the privacy email address specified in Section 17. We may ask for information reasonably necessary to authenticate the request and protect the account, and a parent or lawful guardian may exercise rights concerning a Child’s account, subject to appropriate verification. Institution administrators cannot override a learner’s statutory rights under applicable law.
12.1 In‑app account deletion
SarthiAI provides a visible in‑app settings hub through which you can permanently delete your account. When you trigger account deletion:
- SarthiAI will treat this as withdrawal of consent and loss of purpose for processing your personal data, subject to legal retention obligations;
- SarthiAI will initiate instant erasure of your account profile, learning‑persona parameters and associated personal data from active systems via an automated destructive script, except where retention is required by law for security, regulatory or dispute‑resolution purposes.
For child accounts, parents or lawful guardians may request deletion of the child’s data, and SarthiAI will act on such requests unless retention is legally mandated.
12.2 Web‑portal account deletion
In addition to the in‑app settings hub, users can permanently delete their accounts and associated data through SarthiAI’s dedicated deletion portal at https://sarthiai.co.in/delete-account, which is designed to satisfy Google and Apple in‑app deletion mandates. Deletion requests submitted via this portal are processed using the same automated destructive mechanisms and legal‑retention safeguards described in Section 10.1.
12.3 Grievances and response time
SarthiAI maintains a grievance‑redressal process consistent with the DPDP Act, IT Act rules and any applicable regulations. We will investigate and respond to all formal complaints and grievances via email within a reasonable timeframe taking into account applicable legal requirements and our operational capabilities, rather than a fixed “7‑day” or “90‑day” window.
Users must provide authentic information, not impersonate another person, not suppress material information when seeking correction or erasure, and not submit frivolous or vexatious grievances.
14Service and marketing communications
We may send essential account, security, transaction and service messages that cannot be opted out of while the relevant account or transaction remains active. Marketing messages will be sent only in accordance with applicable law, consent and preferences, and a user may unsubscribe through the message or account settings.
SarthiAI will not direct behavioural marketing to Children and will not use telemetry‑based profiles or cross‑service tracking for personalised advertising to any user.
15Third‑party services and links
The service may link to third‑party websites, content or services. Their privacy practices are governed by their own notices, and a link does not mean SarthiAI endorses the third party. Users should review third‑party terms and privacy notices before providing information or relying on third‑party content.
16Changes to this Policy
We may revise this Policy to reflect product, vendor, security or legal changes. We will update the “Last updated” field and provide reasonable advance or contemporaneous notice of material changes, including via in‑app notifications, email or other effective means.
Where a change introduces a new purpose requiring consent, we will seek that consent before beginning the new processing, and continued use alone will not be treated as consent where the law requires a specific affirmative act.
17Contact and grievance redressal
- Data Fiduciary
- Sarth AI Tech LLP.
- Registered office
- 1010 United Athashri, DN Parande Park Marg, Dhanori, Pune, Maharashtra 411047
- LLP identification number
- ACX-7645
- Grievance Officer
- Rushikesh Patil, rushikesh@sarthiai.co.in
- Security incident contact
- sarthaitech@sarthiai.co.in
- Child‑safety contact
- sarthaitech@sarthiai.co.in
- Support
- help@sarthiai.co.in
Please include the account email or another account identifier and sufficient detail to understand the request. Do not send passwords, one‑time passwords, payment credentials or unnecessary identity documents by email.
18Definitions
- “AI Output”
- means content generated by or through the AI‑enabled features in response to user input.
- “Child”
- has the meaning stated in Section 3.
- “Institution”
- means a school, college, university, coaching centre, employer, training provider or other organisation that contracts for or manages access to SarthiAI.
- “Personal data”, “Data Fiduciary”, “Data Principal” and “Data Processor”
- have the meanings given under applicable Indian data‑protection law, where used in that legal context.
- “User Content”
- means prompts, messages, uploads, feedback and other material submitted by a user or institution.
